TechTalkz.com Logo

Go Back   TechTalkz.com Technology & Computer Troubleshooting Forums > Tech World > Computer Security

Notices

Cannot access Antivirus Sites/Google/Avast etc.

Computer Security


Reply
 
Thread Tools Display Modes
Old 11-01-2009, 10:17 PM   #111
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 23
Posts: 6,621
Thanks: 19
Thanked 645 Times in 603 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

do you have a problem visiting only AVG web site ? Which browser are you using ?

Try visiting any of these :
64.74.243.15
77.67.44.203
64.74.243.14
212.67.88.84
212.96.161.229
__________________
Please don't click here
bakuryu is offline   Reply With Quote
Old 14-01-2009, 12:13 AM   #112
Newbie
 
Join Date: Jan 2009
Age: 19
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 akabane04 is an unknown quantity at this point


OS: Windows XP


Smile Re: Cannot access Antivirus Sites/Google/Avast etc.

i have a prob too but a little diff...i cac't access any AVG,Kaspersky,Norton websites..but other website seems to be okay...and i dont get links when using google...everything seems to be okay except the AVG websites..and my AVG software won't update...i run SPybot..

it some times finds:

-Microsoft.WindowsSecurityCenter_disabled
-Win32.Agent.arnx
-Win32.Agent.ark

but this files are already quaratined on my Spybot...but some this when i reboot the pc then scan again...almost one of these three pops ups..as if they an intaller...BTW i don't have an antivirus...use to have but bcoz of these problems i can't update my AVG for almost a month now..thought it juz encountered some probs so i unintalled it and re-installed it again...but when i try to update it...it wont connect to the AVG server for automatic update..even tried manual but i can't get to AVG website.... WHAT TO DO...

heres my HJT log File BTW...

THNX in advance i know youve help a lot of people her with almost the same problems...juz like to post a diff. one cause mines a little diff. cause like i said i can use google nicely...without like the others saying they're linking to other pages when using google....hope u can fix it....im not doing anything right now ill w8 for ur reply...

Code:
+++++++++++++++++++++++++++++++++++++++++++++++

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:20:34 AM, on 1/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\VM303_STI.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\AhnRpta.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C43 Series" /O5 "LPT1:" /M "Stylus C43"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F392BF83-5053-40F7-BE97-2000B278C06C}: NameServer = 202.78.97.41 210.4.2.61
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5290 bytes

Last edited by Strider; 14-01-2009 at 11:32 AM..
akabane04 is offline   Reply With Quote
Old 14-01-2009, 02:24 AM   #113
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 23
Posts: 6,621
Thanks: 19
Thanked 645 Times in 603 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

First turn OFF system restore in Windows XP.
How to turn off and turn on System Restore in Windows XP

Use CCleaner and clear our all temporary files.

Use taskmanger to kill the process AhnRpta.exe and then use killbox and delete the file
C:\WINDOWS\AhnRpta.exe

Fix the following entry in HijackThis :
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe

if you don't know this page : http://home.sweetim.com/, fix this entry too :
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com


and delete the file C:\WINDOWS\system32\vamsoft.exe using Killbox.

Run combofix, disconnect from net and clear your DNS cache, open command prompt and type :
ipconfig /flushdns

Update virus definitions and run scans as soon as possible.
Download latest AVG virus signature database - January 13th, 2009

Here are some online scanners :
Free Virus Scan - Kaspersky Lab
Free ESET Online Antivirus Scanner
F-Secure Support pages: F-Secure Online Virus Scanner

Free online Trojan Scanner - Scan your system for Trojans

ewido - anti-spyware and anti-malware solutions

If you can access all sites now, you should turn System Restore back on.

Last edited by bakuryu; 14-01-2009 at 02:27 AM..
bakuryu is offline   Reply With Quote
Old 14-01-2009, 03:18 AM   #114
Newbie
 
Join Date: Jan 2009
Age: 19
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 akabane04 is an unknown quantity at this point


OS: Windows XP


Re: Cannot access Antivirus Sites/Google/Avast etc.

BTW already stopped the "C:\WINDOWS\AhnRpta.exe" using task manager right after i send the post i checked it then i noticed it so i "end process" it immediatly...on the part of using "killbox"; is this a program?...if so can u give links on where to download....and can u tell me how to use it or is it "user friendly"..i mean the interface...?

then i dont know that " http://home.sweetim.com/,"..maybe is my sister who used that....

then on combofix...what should come first:

this?..disconnect from net and clear your DNS cache, open command prompt and type :
ipconfig /flushdns

or this?...Run combofix,

then on combofix...i used it once...and its asking for a windows recovery something..(forgot the name of the prog...)can i use combo fix with out it...cause i followed a link in this thread that leads to some site but i think that too is being blocked by my "FxCKNG FRIEND" virus....grrrrr...

lastly about the anti virus..i dont have anything installed at the moment..but i have an AVG free installer...is it possible that the installer can get virus 2..cause i have a partition..and on "C:" is all the files and on "D:" is all the installers...juz installers....then if i install it and downloaded this:

"Update virus definitions and run scans as soon as possible.
Download latest AVG virus signature database - January 13th, 2009"

wil my AVG be fully updated from fresh install...i mean alll the previous updates are there on your linked file???...what about the previous updates they had???...

BTW im staying in touch....please answer all my questions ill be really greatfull...

GODSPEED to U.....LOL
akabane04 is offline   Reply With Quote
Old 14-01-2009, 03:50 AM   #115
Newbie
 
Join Date: Jan 2009
Age: 19
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 akabane04 is an unknown quantity at this point


OS: Windows XP


Re: Cannot access Antivirus Sites/Google/Avast etc.

dang..T_T...did everything except the part of combofix with windows recovery console...only did combofix...then when i tried to install my AVG there was an ERROR....did it again then ERROR again...T_T...

this is my combofix log

Code:
ComboFix 09-01-08.04 - Jarod 2009-01-14  6:07:34.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.512.293 [GMT 8:00]
Running from: d:\pc program installers\Troubleshooting\Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\iq.bat
c:\windows\expiorer.exe
C:\x2tpc.cmd
D:\Autorun.inf
D:\iq.bat
D:\x2tpc.cmd

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_OREANS32
-------\Service_oreans32


(((((((((((((((((((((((((   Files Created from 2008-12-13 to 2009-01-13  )))))))))))))))))))))))))))))))
.

2009-01-14 06:00 . 2009-01-14 06:02    <DIR>    d--------    C:\!KillBox
2009-01-14 05:58 . 2009-01-14 05:58    <DIR>    d--------    c:\program files\CCleaner
2009-01-14 04:38 . 2009-01-14 04:38    <DIR>    d--------    c:\program files\Gpotato
2009-01-14 00:51 . 2009-01-14 00:51    110,929    -r-hs----    c:\windows\system32\olhrwef.exe
2009-01-14 00:51 . 2009-01-14 00:51    95,744    -r-hs----    c:\windows\system32\nmdfgds0.dll
2009-01-13 22:34 . 2009-01-13 22:33    107,692    -r-hs----    C:\bd3q0qix.exe
2009-01-12 13:25 . 2003-06-18 17:31    17,920    --a------    c:\windows\system32\mdimon.dll
2009-01-12 13:25 . 2009-01-12 13:25    376    --a------    c:\windows\ODBC.INI
2009-01-12 13:24 . 2009-01-12 13:24    <DIR>    d--------    c:\program files\Microsoft ActiveSync
2009-01-12 13:22 . 2009-01-12 13:24    <DIR>    d--------    c:\windows\SHELLNEW
2009-01-12 13:22 . 2009-01-12 13:22    <DIR>    d--------    c:\program files\Microsoft.NET
2009-01-12 07:51 . 2009-01-12 07:51    <DIR>    d--------    c:\program files\Common Files\EPSON
2009-01-12 07:51 . 1996-01-09 10:38    283,648    --a------    c:\windows\uninst.exe
2009-01-12 07:51 . 2001-08-23 01:04    139,264    --a------    c:\windows\system32\EBAPI2.dll
2009-01-12 07:48 . 2009-01-12 07:52    <DIR>    d--------    c:\program files\EPSON
2009-01-12 07:48 . 2009-01-12 07:50    16,230    --a------    c:\windows\EPSTPLOG.BAK
2009-01-12 07:45 . 2009-01-12 07:45    <DIR>    d--------    c:\windows\EffectResources
2009-01-12 07:45 . 2009-01-12 07:45    <DIR>    d--------    c:\windows\CatRoot
2009-01-12 07:45 . 2009-01-12 07:45    <DIR>    d--------    c:\program files\Vimicro
2009-01-12 07:45 . 2005-10-27 14:34    390,849    --a------    c:\windows\system32\drivers\usbVM303.sys
2009-01-12 07:45 . 2005-10-31 10:27    270,421    --a------    c:\windows\system32\VM303Prp.Ax
2009-01-12 07:45 . 2005-05-03 15:51    176,128    --a------    c:\windows\amcap.exe
2009-01-12 07:45 . 2005-04-30 18:46    102,400    --a------    c:\windows\VM303Cap.exe
2009-01-12 07:45 . 2005-04-30 18:46    81,920    --a------    c:\windows\system32\VM303STI.dll
2009-01-12 07:45 . 2005-10-25 12:56    61,440    --a------    c:\windows\VM303_STI.EXE
2009-01-12 07:45 . 2005-05-02 16:45    53,248    --a------    c:\windows\Sti303.exe
2009-01-12 07:45 . 2005-05-18 10:55    32,768    --a------    c:\windows\VMZoom.exe
2009-01-12 07:45 . 2005-05-18 10:54    24,576    --a------    c:\windows\VMPipe.dll
2009-01-12 07:45 . 2005-07-06 13:00    3,930    --a------    c:\windows\vm303.mid
2009-01-11 03:00 . 2009-01-11 03:37    <DIR>    d--------    c:\program files\Spybot - Search & Destroy
2009-01-11 03:00 . 2009-01-14 06:00    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-11 01:26 . 2009-01-11 01:26    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\Malwarebytes
2009-01-11 01:26 . 2009-01-11 01:26    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-11 01:19 . 2009-01-11 01:19    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\ErrorSweeper
2009-01-11 00:40 . 2009-01-14 00:41    90,112    -r-hs----    c:\windows\system32\ciuytr0.dll
2009-01-10 23:39 . 2001-08-17 22:36    8,704    --a------    c:\windows\system32\kbdjpn.dll
2009-01-10 23:39 . 2001-08-17 22:36    8,704    --a--c---    c:\windows\system32\dllcache\kbdjpn.dll
2009-01-10 23:39 . 2001-08-17 22:36    8,192    --a------    c:\windows\system32\kbdkor.dll
2009-01-10 23:39 . 2001-08-17 22:36    8,192    --a--c---    c:\windows\system32\dllcache\kbdkor.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a------    c:\windows\system32\kbd106.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a------    c:\windows\system32\kbd101c.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a------    c:\windows\system32\kbd101b.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a--c---    c:\windows\system32\dllcache\kbd106.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a--c---    c:\windows\system32\dllcache\kbd101c.dll
2009-01-10 23:39 . 2001-08-17 14:55    6,144    --a--c---    c:\windows\system32\dllcache\kbd101b.dll
2009-01-10 23:39 . 2001-08-17 14:55    5,632    --a------    c:\windows\system32\kbd103.dll
2009-01-10 23:39 . 2001-08-17 14:55    5,632    --a--c---    c:\windows\system32\dllcache\kbd103.dll
2009-01-10 14:07 . 2009-01-10 14:07    4,096    --a------    c:\windows\system32\01.tmp
2009-01-09 16:44 . 2009-01-13 22:33    90,112    -r-hs----    c:\windows\system32\ciuytr1.dll
2009-01-09 13:24 . 2009-01-09 13:24    <DIR>    d--------    c:\program files\Fussion Dekaron
2009-01-09 07:44 . 2009-01-11 03:23    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-09 05:53 . 2009-01-09 06:22    84,992    -r-hs----    c:\windows\system32\cvnmhg0.dll
2009-01-09 05:52 . 2009-01-09 06:27    <DIR>    d--------    c:\documents and settings\Administrator
2009-01-09 05:47 . 2003-03-19 03:14    499,712    --a------    c:\windows\system32\MSVCP71.dll
2009-01-09 05:23 . 2009-01-09 06:42    <DIR>    d--------    c:\documents and settings\All Users\Application Data\SecTaskMan
2009-01-08 20:34 . 2009-01-09 16:44    121,738    -r-hs----    C:\xcisvxl.com
2009-01-08 14:19 . 2009-01-11 03:26    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Avg8
2009-01-07 01:50 . 2009-01-07 01:50    <DIR>    d--------    c:\documents and settings\All Users\Application Data\TEMP
2009-01-07 01:49 . 2009-01-07 01:49    <DIR>    d--------    c:\program files\Common Files\Download Manager
2009-01-05 14:43 . 2009-01-05 14:43    585    --a------    c:\windows\system32\system.RPT
2009-01-03 18:19 . 2009-01-14 04:11    <DIR>    d--------    c:\program files\MYGAME Launcher
2009-01-03 18:16 . 2009-01-14 04:11    <DIR>    d--------    c:\program files\MYGAME
2009-01-02 01:02 . 2009-01-02 01:05    <DIR>    d--------    c:\documents and settings\All Users\Application Data\WinZip
2008-12-31 20:18 . 2008-12-31 20:18    <DIR>    d--------    c:\windows\Sun
2008-12-30 20:29 . 2008-12-30 20:29    <DIR>    d---s----    c:\documents and settings\Jarod\UserData
2008-12-29 21:00 . 2002-10-08 02:34    73,676    --a------    c:\windows\system32\EBPMON2.DLL
2008-12-29 21:00 . 2002-07-31 10:25    61,440    --a------    c:\windows\system32\ECBTEG.DLL
2008-12-29 21:00 . 2000-06-07 09:01    34,304    --a------    c:\windows\system32\EBPCHP.DLL
2008-12-29 21:00 . 2001-09-04 10:04    182    --a------    c:\windows\system32\EBPPORT.DAT
2008-12-29 20:41 . 2008-12-29 20:43    <DIR>    d--------    c:\program files\Tracker Software
2008-12-29 14:10 . 2008-12-29 14:10    <DIR>    d--------    c:\documents and settings\LocalService\Application Data\Yahoo!
2008-12-28 13:52 . 2009-01-09 05:20    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\LimeWire
2008-12-28 13:50 . 2008-12-28 13:50    <DIR>    d--------    c:\program files\Java
2008-12-28 13:50 . 2008-12-28 13:50    410,984    --a------    c:\windows\system32\deploytk.dll
2008-12-28 13:50 . 2008-12-28 13:50    73,728    --a------    c:\windows\system32\javacpl.cpl
2008-12-28 13:36 . 2008-12-28 13:37    <DIR>    d--------    c:\program files\LimeWire
2008-12-27 16:56 . 2009-01-11 05:18    33,824    --a------    c:\windows\system32\drivers\oreans32.sys
2008-12-26 11:57 . 2008-12-26 11:57    <DIR>    d--------    c:\program files\Common Files\INCA Shared
2008-12-26 11:57 . 2003-07-21 11:17    5,174    --a------    c:\windows\system32\nppt9x.vxd
2008-12-26 11:57 . 2005-01-05 02:43    4,682    --a------    c:\windows\system32\npptNT2.sys
2008-12-24 18:45 . 2008-12-24 18:45    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\DAEMON Tools Pro
2008-12-24 18:45 . 2008-12-24 18:45    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\DAEMON Tools
2008-12-24 18:43 . 2008-12-24 18:43    <DIR>    d--------    c:\program files\DAEMON Tools Lite
2008-12-24 18:43 . 2008-12-24 18:43    <DIR>    d--------    c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-24 18:41 . 2008-12-24 18:41    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\DAEMON Tools Lite
2008-12-24 18:41 . 2008-12-24 18:41    717,296    --a------    c:\windows\system32\drivers\sptd.sys
2008-12-24 14:33 . 2004-08-03 23:08    26,496    --a--c---    c:\windows\system32\dllcache\usbstor.sys
2008-12-24 11:33 . 2008-12-24 11:33    <DIR>    d--------    c:\program files\SystemRequirementsLab
2008-12-24 00:06 . 2008-12-24 00:06    <DIR>    d--------    c:\program files\uTorrent
2008-12-24 00:06 . 2008-12-27 21:36    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\uTorrent
2008-12-23 22:28 . 2009-01-14 03:55    <DIR>    d--------    c:\program files\e-Games
2008-12-23 18:02 . 2003-10-30 09:49    593,408    --a------    c:\windows\system32\drivers\smwdm.sys
2008-12-23 18:02 . 2003-10-23 11:17    100,384    --a------    c:\windows\system32\drivers\aeaudio.sys
2008-12-23 18:02 . 2003-04-08 10:30    3,744    --a------    c:\windows\system32\drivers\smsens.sys
2008-12-23 17:49 . 2007-09-21 17:49    9,216    --a------    c:\windows\system32\drivers\videX32.sys
2008-12-23 17:32 . 2008-12-23 17:32    <DIR>    d--------    C:\swsetup
2008-12-23 17:28 . 2008-12-23 17:29    <DIR>    d--h-c---    c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-12-23 15:53 . 2008-12-23 15:53    <DIR>    d--------    c:\program files\Orbitdownloader
2008-12-23 15:53 . 2009-01-14 05:52    <DIR>    d--------    C:\Downloads
2008-12-23 15:53 . 2009-01-14 04:21    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\Orbit
2008-12-23 15:25 . 2006-11-01 23:21    319,456    --a------    c:\windows\system32\difxapi.dll
2008-12-23 15:25 . 2006-10-27 08:26    69,632    --a------    c:\windows\system32\vuins32.dll
2008-12-23 15:25 . 2008-09-22 03:41    43,520    --a------    c:\windows\system32\drivers\fetnd5bv.sys
2008-12-23 15:23 . 2007-06-27 14:42    207,488    -ra------    c:\windows\system32\drivers\vinyl97.sys
2008-12-23 15:20 . 2008-12-23 18:02    <DIR>    d----c---    c:\windows\system32\DRVSTORE
2008-12-23 14:43 . 2009-01-10 17:42    <DIR>    d--h-----    C:\$AVG8.VAULT$
2008-12-23 14:08 . 2008-12-23 14:08    <DIR>    d--------    c:\program files\AVG
2008-12-23 07:46 . 2008-12-23 07:46    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\Yahoo!
2008-12-23 02:11 . 2008-12-23 02:11    <DIR>    d--------    c:\documents and settings\Jarod\Application Data\ATI

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-11 23:45    ---------    d--h--w    c:\program files\InstallShield Installation Information
2009-01-11 23:45    ---------    d-----w    c:\program files\Common Files\InstallShield
2009-01-08 06:20    ---------    d-----w    c:\program files\Google
2009-01-08 06:16    ---------    d-----w    c:\program files\Yahoo!
2008-12-22 23:47    ---------    d-----w    c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-22 18:09    ---------    d-----w    c:\program files\My Company Name
2008-12-22 18:09    ---------    d-----w    c:\program files\Common Files\ATI Technologies
2008-12-22 18:07    ---------    d-----w    c:\program files\ATI Technologies
2008-12-22 17:57    ---------    d-----w    c:\program files\Analog Devices
2008-12-22 17:44    ---------    d-----w    c:\program files\microsoft frontpage
2004-08-03 22:56    167,324    --sha-r    c:\windows\system32\vbfbvh.dll
.

(((((((((((((((((((((((((((((   snapshot@2009-01-11_ 2.45.12.21   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-12 05:24:00    110,592    ----a-w    c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-01-12 05:24:00    64,088    ----a-w    c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-01-12 05:24:00    229,376    ----a-w    c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2009-01-12 05:24:01    4,096    ----a-w    c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-01-12 05:24:00    223,800    ----a-w    c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-01-12 05:24:01    16,384    ----a-w    c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2002-07-25 09:13:18    24,576    ----a-w    c:\windows\Downloaded Program Files\dwusplay.dll
+ 2002-07-25 09:13:12    196,608    ----a-w    c:\windows\Downloaded Program Files\dwusplay.exe
+ 2002-07-25 09:05:32    172,032    ----a-w    c:\windows\Downloaded Program Files\isusweb.dll
+ 2004-05-19 08:38:00    25,600    ----a-w    c:\windows\EffectResources\VM0303\borlndmm.dll
+ 2004-05-19 08:38:00    1,496,064    ----a-w    c:\windows\EffectResources\VM0303\cc3250mt.dll
+ 2005-06-22 05:52:30    612,352    ----a-w    c:\windows\EffectResources\VM0303\FrameWizard.exe
+ 2009-01-12 05:25:31    593,920    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-01-12 05:25:31    12,288    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-01-12 05:25:31    86,016    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-01-12 05:25:30    135,168    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-01-12 05:25:31    11,264    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-01-12 05:25:31    27,136    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-01-12 05:25:31    4,096    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-01-12 05:25:31    794,624    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-01-12 05:25:30    249,856    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-01-12 05:25:30    61,440    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-01-12 05:25:31    23,040    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-01-12 05:25:30    286,720    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-01-12 05:25:30    409,600    ----a-r    c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2004-08-03 22:56:50    78,848    ----a-w    c:\windows\system32\afmain0.dll
+ 2004-08-03 22:56:50    78,848    ----a-w    c:\windows\system32\afmain1.dll
+ 2004-08-03 15:10:18    17,024    -c--a-w    c:\windows\system32\dllcache\ccdecode.sys
+ 2004-08-03 16:56:44    47,616    -c--a-w    c:\windows\system32\dllcache\iyuv_32.dll
+ 2004-08-03 14:58:40    5,504    -c--a-w    c:\windows\system32\dllcache\mstee.sys
+ 2004-08-03 16:56:46    17,408    -c--a-w    c:\windows\system32\dllcache\msyuv.dll
+ 2004-08-03 15:10:30    85,376    -c--a-w    c:\windows\system32\dllcache\nabtsfec.sys
+ 2004-08-03 15:10:14    10,880    -c--a-w    c:\windows\system32\dllcache\ndisip.sys
+ 2004-08-03 15:10:18    11,136    -c--a-w    c:\windows\system32\dllcache\slip.sys
+ 2004-08-03 15:10:14    15,360    -c--a-w    c:\windows\system32\dllcache\streamip.sys
+ 2001-08-17 14:36:34    8,192    -c--a-w    c:\windows\system32\dllcache\tsbyuv.dll
+ 2004-08-03 16:56:48    53,760    -c--a-w    c:\windows\system32\dllcache\vfwwdm32.dll
+ 2004-08-03 15:10:22    19,328    -c--a-w    c:\windows\system32\dllcache\wstcodec.sys
+ 2004-08-03 15:10:18    17,024    ----a-w    c:\windows\system32\drivers\CCDECODE.sys
+ 2004-08-03 14:58:40    5,504    ----a-w    c:\windows\system32\drivers\MSTEE.sys
+ 2004-08-03 15:10:30    85,376    ----a-w    c:\windows\system32\drivers\NABTSFEC.sys
+ 2004-08-03 15:10:14    10,880    ----a-w    c:\windows\system32\drivers\NdisIP.sys
+ 2004-08-03 15:10:18    11,136    ----a-w    c:\windows\system32\drivers\SLIP.sys
+ 2004-08-03 15:10:14    15,360    ----a-w    c:\windows\system32\drivers\StreamIP.sys
+ 2004-08-03 15:10:22    19,328    ----a-w    c:\windows\system32\drivers\WSTCODEC.SYS
+ 2003-08-03 02:56:16    1,146,184    ----a-w    c:\windows\system32\FM20.DLL
+ 2003-07-14 14:57:04    32,584    ----a-w    c:\windows\system32\FM20ENU.DLL
- 2008-12-26 19:09:57    91,088    ----a-w    c:\windows\system32\FNTCACHE.DAT
+ 2009-01-12 10:30:59    189,000    ----a-w    c:\windows\system32\FNTCACHE.DAT
+ 2002-08-20 21:10:16    204,800    ----a-w    c:\windows\system32\INKED.DLL
- 2004-08-03 23:05:44    47,616    ----a-w    c:\windows\system32\iyuv_32.dll
+ 2004-08-03 16:56:44    47,616    ----a-w    c:\windows\system32\iyuv_32.dll
+ 1998-06-17 11:08:32    53,248    ----a-w    c:\windows\system32\MFC42ENU.DLL
- 2004-08-03 23:05:44    294,912    ----a-w    c:\windows\system32\msh263.drv
+ 2004-08-03 16:56:58    294,912    ----a-w    c:\windows\system32\msh263.drv
+ 2000-05-11 05:06:20    397,312    ----a-w    c:\windows\system32\MSRDO20.DLL
+ 2000-05-23 14:45:58    118,784    ----a-w    c:\windows\system32\MSSTDFMT.DLL
+ 1998-08-09 03:07:34    94,208    ----a-w    c:\windows\system32\MSSTKPRP.DLL
- 2004-08-03 23:05:44    17,408    ----a-w    c:\windows\system32\msyuv.dll
+ 2004-08-03 16:56:46    17,408    ----a-w    c:\windows\system32\msyuv.dll
+ 2000-04-03 09:52:54    151,552    ----a-w    c:\windows\system32\RDOCURS.DLL
+ 1998-03-24 13:54:08    15,872    ----a-w    c:\windows\system32\SCP32.DLL
+ 2002-06-12 04:00:00    315,392    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DCON02.DLL
+ 2002-12-06 05:00:00    45,171    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DDSP13.DLL
+ 2002-08-16 04:00:00    115,200    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DHMM11.DLL
+ 2002-01-11 04:00:00    143,872    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DHT3R0.DLL
+ 2002-12-25 04:00:00    1,076,224    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DI06YE.DLL
+ 2003-01-14 04:00:00    395,776    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DJB304.DLL
+ 2002-12-26 05:00:00    106,058    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DMAI14.DLL
+ 1999-03-08 03:00:00    148,992    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DMSG00.EXE
+ 2002-07-30 04:00:00    142,848    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DPPE03.EXE
+ 2002-07-15 04:00:00    509,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DPUI03.DLL
+ 2002-04-24 04:00:00    1,171,968    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DSU0AE.DLL
+ 2003-01-23 05:00:00    330,512    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DU16YE.DLL
+ 2002-07-15 04:00:00    74,240    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_DUMWT2.DLL
+ 2002-12-25 01:01:00    103,936    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_H19UIW.DLL
+ 2002-12-24 01:00:00    685,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_H290Y2.DLL
+ 2002-12-24 01:00:00    76,800    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_H2E0Z2.DLL
+ 2000-05-16 02:00:00    60,416    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S00RP2.EXE
+ 2001-10-01 01:20:00    57,344    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S01C00.EXE
+ 2001-09-21 01:01:00    32,768    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S01CE0.DLL
+ 2002-12-10 03:06:00    75,776    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE
+ 2002-10-02 03:04:00    101,888    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S10MT2.EXE
+ 2002-07-01 03:02:00    69,632    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S10RN2.EXE
+ 2003-01-22 03:10:00    206,336    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S1T0A2.EXE
+ 2002-12-25 03:00:00    288,256    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S290Y2.DLL
+ 2003-01-22 03:00:00    179,712    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S2E0Z2.DLL
+ 2002-12-25 03:00:00    3,258    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_S2X0Z2.DAT
+ 2002-11-28 03:03:00    77,312    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_SECK32.DLL
+ 2002-08-23 04:02:00    131,072    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_SIINS2.EXE
+ 2001-04-27 03:01:00    52,736    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\E_SPSU01.EXE
+ 2002-10-21 03:23:00    797,191    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EB_SET06.EXE
+ 2001-06-13 04:00:00    30,720    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPIBSR30.EXE
+ 2001-11-02 04:00:00    52,736    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPIPGI10.DLL
+ 1999-06-09 01:07:00    54,272    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPSET32.DLL
+ 2002-12-13 05:57:00    414,976    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPUPDATE.EXE
+ 2002-10-28 06:06:20    125,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPUTIX24.DLL
+ 2002-10-28 06:06:20    45,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\EPUTIX24.EXE
+ 2003-06-18 09:31:44    758,784    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2003-06-18 09:31:46    35,328    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2002-12-13 05:57:00    48,128    ----a-w    c:\windows\system32\spool\drivers\w32x86\3\SETUP32.DLL
+ 2002-12-25 01:01:00    103,936    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_H19UIW.DLL
+ 2001-10-01 01:20:00    57,344    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S01C00.EXE
+ 2001-09-21 01:01:00    32,768    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S01CE0.DLL
+ 2002-12-10 03:06:00    75,776    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S10IC2.EXE
+ 2002-10-02 03:04:00    101,888    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S10MT2.EXE
+ 2002-07-01 03:02:00    69,632    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S10RN2.EXE
+ 2003-01-22 03:10:00    206,336    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S1T0A2.EXE
+ 2002-12-25 03:00:00    288,256    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S290Y2.DLL
+ 2003-01-22 03:00:00    179,712    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S2E0Z2.DLL
+ 2002-12-25 03:00:00    3,258    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_S2X0Z2.DAT
+ 2002-11-28 03:03:00    77,312    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_SECK32.DLL
+ 2002-08-23 04:02:00    131,072    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_SIINS2.EXE
+ 2001-04-27 03:01:00    52,736    ----a-w    c:\windows\system32\spool\drivers\w32x86\E_SPSU01.EXE
+ 2002-10-21 03:23:00    797,191    ----a-w    c:\windows\system32\spool\drivers\w32x86\EB_SET06.EXE
- 2002-06-11 20:00:00    315,392    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DCON02.DLL
+ 2002-06-12 04:00:00    315,392    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DCON02.DLL
- 2002-12-05 21:00:00    45,171    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DDSP13.DLL
+ 2002-12-06 05:00:00    45,171    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DDSP13.DLL
- 2002-08-15 20:00:00    115,200    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DHMM11.DLL
+ 2002-08-16 04:00:00    115,200    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DHMM11.DLL
- 2002-01-10 20:00:00    143,872    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DHT3R0.DLL
+ 2002-01-11 04:00:00    143,872    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DHT3R0.DLL
- 2002-12-24 20:00:00    1,076,224    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DI06YE.DLL
+ 2002-12-25 04:00:00    1,076,224    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DI06YE.DLL
- 2003-01-13 20:00:00    395,776    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DJB304.DLL
+ 2003-01-14 04:00:00    395,776    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DJB304.DLL
- 2002-12-25 21:00:00    106,058    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DMAI14.DLL
+ 2002-12-26 05:00:00    106,058    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DMAI14.DLL
- 1999-03-07 19:00:00    148,992    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DMSG00.EXE
+ 1999-03-08 03:00:00    148,992    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DMSG00.EXE
- 2002-07-29 20:00:00    142,848    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DPPE03.EXE
+ 2002-07-30 04:00:00    142,848    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DPPE03.EXE
- 2002-07-14 20:00:00    509,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DPUI03.DLL
+ 2002-07-15 04:00:00    509,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DPUI03.DLL
- 2002-04-23 20:00:00    1,171,968    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DSU0AE.DLL
+ 2002-04-24 04:00:00    1,171,968    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DSU0AE.DLL
- 2003-01-22 21:00:00    330,512    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DU16YE.DLL
+ 2003-01-23 05:00:00    330,512    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DU16YE.DLL
- 2002-07-14 20:00:00    74,240    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DUMWT2.DLL
+ 2002-07-15 04:00:00    74,240    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_DUMWT2.DLL
- 2002-12-23 17:00:00    685,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_H290Y2.DLL
+ 2002-12-24 01:00:00    685,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_H290Y2.DLL
- 2002-12-23 17:00:00    76,800    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_H2E0Z2.DLL
+ 2002-12-24 01:00:00    76,800    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_H2E0Z2.DLL
- 2000-05-15 18:00:00    60,416    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_S00RP2.EXE
+ 2000-05-16 02:00:00    60,416    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\E_S00RP2.EXE
- 2001-06-12 20:00:00    30,720    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPIBSR30.EXE
+ 2001-06-13 04:00:00    30,720    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPIBSR30.EXE
- 2001-11-01 20:00:00    52,736    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPIPGI10.DLL
+ 2001-11-02 04:00:00    52,736    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPIPGI10.DLL
- 1999-06-08 17:07:00    54,272    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPSET32.DLL
+ 1999-06-09 01:07:00    54,272    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPSET32.DLL
- 2002-12-12 21:57:00    414,976    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUPDATE.EXE
+ 2002-12-13 05:57:00    414,976    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUPDATE.EXE
- 2002-10-27 22:06:20    125,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUTIX24.DLL
+ 2002-10-28 06:06:20    125,440    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUTIX24.DLL
- 2002-10-27 22:06:20    45,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUTIX24.EXE
+ 2002-10-28 06:06:20    45,056    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\EPUTIX24.EXE
- 2002-12-12 21:57:00    48,128    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\SETUP32.DLL
+ 2002-12-13 05:57:00    48,128    ----a-w    c:\windows\system32\spool\drivers\w32x86\epsonstylus_c439909\SETUP32.DLL
+ 2002-12-13 05:57:00    414,976    ----a-w    c:\windows\system32\spool\drivers\w32x86\EPUPDATE.EXE
+ 2003-06-18 09:31:44    758,784    ----a-w    c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2003-06-18 09:31:46    35,328    ----a-w    c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2002-12-13 05:57:00    48,128    ----a-w    c:\windows\system32\spool\drivers\w32x86\SETUP32.DLL
+ 2003-06-18 09:31:48    18,944    ----a-w    c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
- 2001-08-23 11:00:00    8,192    ----a-w    c:\windows\system32\tsbyuv.dll
+ 2001-08-17 14:36:34    8,192    ----a-w    c:\windows\system32\tsbyuv.dll
+ 1999-11-24 10:40:50    40,960    ----a-w    c:\windows\system32\VBAME.DLL
+ 2004-08-03 16:56:48    53,760    ----a-w    c:\windows\system32\vfwwdm32.dll
+ 2002-08-20 21:13:12    189,952    ----a-w    c:\windows\system32\WISPTIS.EXE
+ 2009-01-13 22:11:51    16,384    ----atw    c:\windows\Temp\Perflib_Perfdata_61c.dat
+ 2009-01-13 22:11:44    16,384    ----atw    c:\windows\Temp\Perflib_Perfdata_a0.dat
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-28 136600]
"BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 61440]
"EPSON Stylus C43 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-12-10 75776]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4C402F-882A-4526-8C08-51278EA437C1}"= "c:\windows\system32\afmain1.dll" [2004-08-04 78848]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3379:TCP"= 3379:TCP:aqsvf

S4 nwsxwy;System Security;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
nwsxwy

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be2abf86-d184-11dd-80a6-0011d83f1c71}]
\Shell\AutoRun\command - G:\x2tpc.cmd
\Shell\open\Command - G:\x2tpc.cmd
.
Contents of the 'Scheduled Tasks' folder

2009-01-13 c:\windows\Tasks\ErrorSweeper Scheduled Scan.job
- c:\program files\ErrorSweeper\ErrorSweeper.exe []

2009-01-13 c:\windows\Tasks\ErrorSweeper Scheduled Scan.job
- c:\program files\ErrorSweeper []
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-vamsoft - c:\windows\system32\vamsoft.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*Yahoo! SearchBar Home Page
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jarod\Application Data\Mozilla\Firefox\Profiles\y5zdofx3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 06:11:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@?????????????? 

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nwsxwy]
"ServiceDll"="c:\windows\system32\vbfbvh.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-01-14  6:14:57 - machine was rebooted [Jarod]
ComboFix-quarantined-files.txt  2009-01-13 22:14:55
ComboFix2.txt  2009-01-10 18:45:46

Pre-Run: 17,502,326,784 bytes free
Post-Run: 17,490,616,320 bytes free

418
.....................................................
could we somehow make a remote assistance?? can u provide that???... im trusting u that much... i really want this pc to be fixed T_T....

Last edited by Strider; 14-01-2009 at 11:33 AM..
akabane04 is offline   Reply With Quote
Old 14-01-2009, 06:33 AM   #116
Newbie
 
Join Date: Jan 2009
Posts: 16
Thanks: 5
Thanked 0 Times in 0 Posts
Rep Power: 0 earthchild57 is an unknown quantity at this point


OS: Windows XP


Re: Cannot access Antivirus Sites/Google/Avast etc.

Has anyone had a chance to look at my combo fix log yet?

TechTalkz.com Technology & Computer Troubleshooting Forums - View Single Post - Cannot access Antivirus Sites/Google/Avast etc.

I think maybe it got lost in the shuffle. I can certainly see how that could happen. I know you guys are volunteering here so I'm not being demanding or anything. I appreciate what you're doing more than I can say.

An additional problem has come up. I discovered today that there was a virus on both of my jump drives. I hadn't even thought of that happening but when I used them at school today, their Norton antivirus caught them and put them in quarantine. It said it couldn't delete them. Does quarantine mean they're gone or do I need to do something else with that? This is becoming a nightmare. Please help.

Thanks bunches!

Vicki
earthchild57 is offline   Reply With Quote
Old 14-01-2009, 08:52 AM   #117
Newbie
 
Join Date: Jan 2009
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 crerma is an unknown quantity at this point


OS: Windows XP


Cannot access Antivirus Sites/did defender/macfee etc.

Hi All,

I have a issues same like most of the others, i cannot access or update AV sits and tools, this is my HJT log, Please help

Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:31:14 AM, on 1/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - S-1-5-18 Startup: Registration TMNT.LNK = G:\TMNT\Registration\RegistrationReminder.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Registration TMNT.LNK = G:\TMNT\Registration\RegistrationReminder.exe (User 'Default user')
O4 - Startup: Registration TMNT.LNK = G:\TMNT\Registration\RegistrationReminder.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2CE1AB5-7D8B-4732-83DA-A9E00901275F}: NameServer = 123.231.0.167 123.231.0.181
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9912 bytes

Last edited by Strider; 14-01-2009 at 11:34 AM..
crerma is offline   Reply With Quote
Old 14-01-2009, 09:30 AM   #118
Founder
 
Strider's Avatar
 
Join Date: Nov 2005
Location: The Last City Zion!
Posts: 3,539
Thanks: 287
Thanked 345 Times in 298 Posts
Rep Power: 62 Strider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just Great


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7 Linux


Re: Cannot access Antivirus Sites/Google/Avast etc.

@akabane04: After running the Combofix, can you access the antivirus websites now? i.e. is your original problem resolved?

Please provide a Hiajckthis log to see the current status of your machine.



Quote:
then when i tried to install my AVG there was an ERROR
What is the error message it's showing? Could you post a screenshot?

Last edited by Strider; 14-01-2009 at 11:02 AM..
Strider is offline   Reply With Quote
Old 14-01-2009, 11:11 AM   #119
Founder
 
Strider's Avatar
 
Join Date: Nov 2005
Location: The Last City Zion!
Posts: 3,539
Thanks: 287
Thanked 345 Times in 298 Posts
Rep Power: 62 Strider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just Great


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7 Linux


Re: Cannot access Antivirus Sites/Google/Avast etc.

@earthchild57:

Hi Vicki,

Your Combofix log don't have much problems. But a latest Hijackthis log will be good to see the current status of your computer.

Quote:
Does quarantine mean they're gone or do I need to do something else with that? This is becoming a nightmare.
Quarantine is the way to keep the rouge files in an encrypted vault so that it won't hamrm the computer. It is perfectly safe now.

Btw. From where did those drive get infected? Are you using it in any other computers other than yours?

I suggest you install a good Antivirus ( like NOD32/Kaspersky/Norton) in your home PC ASAP.
Strider is offline   Reply With Quote
Thanked Users:
earthchild57 (14-01-2009)
Old 14-01-2009, 11:58 AM   #120
Founder
 
Strider's Avatar
 
Join Date: Nov 2005
Location: The Last City Zion!
Posts: 3,539
Thanks: 287
Thanked 345 Times in 298 Posts
Rep Power: 62 Strider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just GreatStrider is just Great


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7 Linux


Re: Cannot access Antivirus Sites/Google/Avast etc.

Hi crerma,

Your log seems to be fine for me. Bakuryu, a second opinion is welcome.

Any way try these steps:

1. In Hijackthis fix the following entry

Quote:
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2CE1AB5-7D8B-4732-83DA-A9E00901275F}: NameServer = 123.231.0.167 123.231.0.181
2. Download and Run combofix as per the instructions here.

3. Open the hosts file in notepad and check if it's clean.

Quote:
c:\windows\system32\drivers\etc\hosts
4. Disconnect from internet and clear your DNS cache by typing in the following command in Run box:

Code:
ipconfig /flushdns
5. Lastly install a good Antivirus ( like NOD32/Kaspersky/Norton) in your computer ASAP.
Strider is offline   Reply With Quote
Reply

Tags
antivirus, cleanup, infection, virus, virus removal

Thread Tools
Display Modes



< Windows Help - MS Office Help - Hardware Support >


New To Site? Need Help?

All times are GMT +5.5. The time now is 04:50 AM.


vBulletin, Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO
Copyright © 2005-2009, TechTalkz.com. All Rights Reserved - Privacy Policy
Valid XHTML 1.0 Transitional